<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Development of an Analytical Data Processing System for Monitoring Information Security of an Informatization Object's Information Support's Structure Models</article-title>
      </title-group>
      <contrib-group>
        <aff id="aff0">
          <label>0</label>
          <institution>Plekhanov Russian University of Economics</institution>
          ,
          <addr-line>Stremyanny lane 36, 117997 Moscow</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <fpage>0000</fpage>
      <lpage>0002</lpage>
      <abstract>
        <p>The work is aimed at improving the efficiency of information security management of an informatization object based on optimizing the structure of information support for an automated information security monitoring data processing system. It is considered, that a distributed information security monitoring data processing system built on the basis of a universal information security event management system. The technical support of this system is a local computer network, which includes information security tools. Information security tools and network nodes are the main sources of information about information security events. Taking into account the large volumes of data on information security (IS) events in the analytical data processing system (ADPS), it is necessary to optimize the ADPS information support's structure, taking into account the structure and technical characteristics of the LAN. The article proposes mathematical models for optimizing the structure of information support for an automated information security monitoring data processing system according to the maximin's criterion of information support for ADPS usefulness and the criterion for the maximum relevance of information support distributed over LAN nodes. All problems are reduced to typical problems of integer mathematical programming, for the solution of which classical well-known methods can be used. The proposed approach makes it possible to increase the efficiency of the procedure for identifying information security incidents by organizing a rational exchange of information in an automated data processing system for information security of an informatization object's monitoring, taking into account the usefulness of analytical data processing procedures.</p>
      </abstract>
      <kwd-group>
        <kwd>Information Security</kwd>
        <kwd>Security Information Event Management</kwd>
        <kwd>Information Support</kwd>
        <kwd>Structure Models</kwd>
        <kwd>Theory of Utility</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>Currently, in the field of information security (IS) management of modern objects of
informatization, a group of tasks for managing IS incidents is distinguished, which</p>
      <p>includes the following main tasks: monitoring IS events of informatization objects
and identifying IS incidents; registration of information security incidents; analysis of
information security incidents; informing the administration about all cases of
information security violations; collection of evidence and evidence for response to
incidents of information security and others. From a practical point of view, one of the
most effective approaches to creating information security monitoring is the
SIEMsystems usage [1-4].</p>
      <p>SIEM class solutions provide management of information and security events,
implementing the functions of collecting and storing, processing and analyzing
registered security events in order to identify and analyze incidents, as well as check the
compliance of the IS management system with existing requirements and standards
[5]. At the same time, most SIEM solutions include components of an analytical data
processing system (ADPS) for monitoring information security of an informatization
object, for example, a technology for identifying dependencies between individual
information security events, used indicators of the state of the protected infrastructure,
etc.</p>
      <p>However, the main disadvantage of such systems is the relatively long period
required for them to analyze the data and make a decision about whether this
information security event, or their combination, is an information security incident or not
[6-8].</p>
      <p>This drawback is based on the contradiction between the distributed nature of
information sources about an information security event (as a rule, these sources are
information security tools integrated in a local area network (LAN)) and a centralized
way of making decisions on actions with information security incidents.</p>
      <p>To resolve this contradiction it is necessary, on the one hand, to provide the
decision-making process with the most complete information, and on the other hand, this
information must be relevant. Considering the large volumes of data on IS events in
ADPS, it is necessary to optimize the structure of information support for ADPS,
considering the structure and technical characteristics of the LAN. Therefore, the task
of developing models of the structure of information support of ADPS for monitoring
the information security of an object of informatization is relevant.
2.</p>
      <p>Statement of developing information support structure
models for an analytical data processing system for
monitoring the information security of an informatization
object using the theory of utility</p>
      <p>In this work, it is assumed that ADPS for information security monitoring,
operating in the information security management system (ISMS) of an
informatization object, built on the basis of a LAN, is used as an organizational and
technical form of information security processes management, including information
security monitoring processes occurring in real time. Such systems place increased
demands on the efficiency of data processing in real operating conditions. For
example, a fast response ISMS for monitoring the information security of an object related
to a critical information infrastructure impose increased requirements both on the
safety of the data used in these systems and on the promptness of their processing.
The solution to the problem of effective data processing in such systems is relevant
and requires taking into account a number of factors, such as: distributed data
processing, strict time constraints for obtaining a response to a request when making a
decision, large amounts of data for analytical research and identification of
information security incidents, etc.</p>
      <p>Output information is understood as information obtained because of the
performance of data analytics functions and issued to the object of its activity, users, or
other systems. The quality of output information in ADPS for monitoring the
information security of an informatization object is understood as a set of information
properties that determine its suitability to meet the needs of a security officer in the
timely identification and investigation of information security incidents.</p>
      <p>One of the main systemic methods for improving the quality of output information
in ADPS for monitoring the information security of an informatization object, aimed
at improving the probabilistic and temporal characteristics of the functioning of
systems, is computer modeling.</p>
      <p>The features of the ADPS functioning for monitoring the information security of an
informatization object based on a LAN allow, when solving problems of improving
the quality of output information using computer modeling, in addition to traditional
means of determining the optimal points from the corporate information system
information security level’s point of view storage points of information elements, use
the methods of theory utility, allowing to evaluate the useful effect of placing
information elements in certain computing nodes [9]. They take into account the property
of information reliability not only as an error-free property (that is, the
correspondence of the data received by the consumer with the data generated at the source), but
also as a property of relevance (maintaining a sufficient degree of compliance with
the real state of accounting objects at the time of using this information).</p>
      <p>The essence of the application of the method based on the theory of utility and
computer modeling to determine the computational nodes that are the storage location
for information elements to optimize the use of these nodes and the distribution of
information elements among the nodes is that, in most cases, information security
incident management tasks make it possible to pre-select the necessary datasets
(intermediate arrays) and distribute them across the LAN nodes for immediate use in the
future, i.e. it is necessary to define in advance the information exchange of data on IS
events in ADPS. The information support of ADPS for monitoring the informatization
object information security can include both the data stating the informatization object
information security state itself, obtained directly from information security services,
as well as their copies and / or prehistories received in LAN nodes in places where
they are used by ADPS for monitoring the informatization object information
security[ 10-11].</p>
      <p>
        Thus, in some cases it is allowed
[X (t) -X (t-т)] ≤e, e&gt; 0, VT, T£ [0, t]
(
        <xref ref-type="bibr" rid="ref1">1</xref>
        )
where X (t), X (t- T) are the corresponding values of any parameter of the
information element at time t and (t- т), S is the absolute limit of the permissible deviations
of the real degree of utility of the item from its expected degree of utility. The
fulfillment of inequality (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) determines the usefulness of the information element when it is
processed at the LAN node on the interval T. In this case, the degree of usefulness of
the information support of ADPS is understood as the probability of the relevance of
all its constituent elements on the interval T.
      </p>
      <p>One of the main tasks of synthesizing the structure of information support of
ADPS for monitoring the information security of an informatization object, solved at
the stage of predesign analysis, is the task of determining the optimal content of
ADPS information support and its placement on LAN nodes.</p>
      <p>
        Let J - the number of LAN nodes, I - the number of information elements of the
system; a; is the relative utility of the i-th information element (the degree of utility
determined for a given time period T), t-j, is the time of transmission of the i-th
information element from the j-th to the j'-th LAN node, b; is the value of the i-th
information element’s volume, W = (Ajj) is a matrix of interconnections of information
sources (LAN nodes) and information elements,
(
        <xref ref-type="bibr" rid="ref2">2</xref>
        )
      </p>
      <p>P = (Pij) is the marginal utility matrix, where P;j are the weighted estimates of the
utility for the user, obtained from placing each additional i- th information element in
the j-th LAN node,</p>
      <p>Pij ∈ [0,1], ∀i, i = 1,I,∀j, j = 1,J.</p>
      <p>The ways of constructing the matrix P are determined by the specific conditions of
using ADPS for monitoring the information security of an informatization object. In
particular, the estimate of the marginal utility for the user as a result of placing each
additional i-th information element in the j-th LAN node can be made up of objective
estimates (for example, the time of transmission of the i-th information element to the
j-th node from other LAN nodes) and subjective assessment of the probability of
obtaining a positive marginal utility in relation to the need to transfer the i-th
information element to the j-th node of the LAN [12].</p>
      <p>The usefulness of the i-th information item is determined with taking into account
the quality of the analytical procedures performed in the j-th node using the i-th
information item. Often, the quality of the procedures contradicts the required
probabilistic and temporal characteristics of the information security monitoring process and
identifying information security incidents. For example, processing procedures,
procedures of neural and neuro-fuzzy data processing technologies, etc. [13] Therefore,
the value of the positive marginal utility of placing a copy and
/ or the prehistory of an information element about an information security event of an
informatization object in a specific LAN node, including information security
services, is mainly influenced by the following factors:</p>
      <p>The effectiveness of the procedure for processing data on the state of information
security, performed in this LAN node;</p>
      <p>The required completeness and relevance of the initial data for identifying
information security incidents.</p>
      <p>Then, using the following variables:</p>
      <p>,,</p>
      <p>The degree of ADPS information support’s usefulness for monitoring the
information security of an informatization object E(xij) can be determined by the following
formula:</p>
      <p>In cases where geographically distributed systems consist of homogeneous
elements based on the degree of risk of information security incidents, it is advisable to
use the maximin criterion of the usefulness of information security of an information
security object as the main criterion for synthesizing an ASOD for monitoring the
information security of an informatization object for monitoring the information
security of an informatization object, for complex, complex systems with a low degree of
centralization of management, it is advisable to use the criterion of the maximum
relevance of information support distributed over LAN nodes.</p>
      <p>The task of designing the information support of ADPS for monitoring the
information security of an informatization object structure according to the first criterion is
as follows.</p>
      <p>To find:
with restrictions:
- on the degree of ADPS for monitoring the information security of an object of
informatization information support’s usefulness:</p>
      <p>
        where E* is the minimum permissible degree of ADPS for monitoring the
information security of an object of informatization information support’s usefulness;
for the relative time of information elements transfer between LAN nodes;
(
        <xref ref-type="bibr" rid="ref3">3</xref>
        )
(
        <xref ref-type="bibr" rid="ref5">5</xref>
        )
(
        <xref ref-type="bibr" rid="ref6">6</xref>
        )
where T* is the maximum permissible relative time of transmission of information
elements (on the interval τ) between LAN nodes;
- on the amount of memory of the -th LAN node;
where Bj* is the maximum allowable memory size of the j-th node;
- for the absence of duplication of the information element in the LAN nodes:
Statement 1. The solution to problem (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) - (
        <xref ref-type="bibr" rid="ref5">5</xref>
        ) is admissible for E
fulfillment of constraints (
        <xref ref-type="bibr" rid="ref6">6</xref>
        ) - (
        <xref ref-type="bibr" rid="ref9">9</xref>
        ).
      </p>
      <p>
        Evidence. Let
⟹ 1 and the
∀
∀
(
        <xref ref-type="bibr" rid="ref8">8</xref>
        )
(
        <xref ref-type="bibr" rid="ref9">9</xref>
        )
(
        <xref ref-type="bibr" rid="ref10">10</xref>
        )
Then constraints (
        <xref ref-type="bibr" rid="ref6">6</xref>
        ), (
        <xref ref-type="bibr" rid="ref7">7</xref>
        ) will have the following form:
      </p>
      <p>
        Taking the logarithm of the first inequality of system (
        <xref ref-type="bibr" rid="ref10">10</xref>
        ) and expanding the
logarithm function in a power series, we successively obtain:
where χ is the remainder of the series.
      </p>
      <p>
        Obviously, ⟹ , constraint (
        <xref ref-type="bibr" rid="ref7">7</xref>
        ) is more stringent. The proposed analysis of the
rigidity of constraints can be used to reduce the dimension of tasks with specific
initial data, especially for information security monitoring systems for complex objects
of informatization of large dimensions and intensive exchange of information.
      </p>
      <p>Modern ADPS for monitoring the information security of an informatization
object, operating on a LAN basis, is critical to the amount of information transmitted
through communication channels. Therefore, the following problem of determining
the ADPS for monitoring the information security of an informatization object
information support structure by the criterion of uniform usefulness of its components can
be considered the most urgent.</p>
      <p>To find:
,
∀</p>
      <p>
        ,
∀
subject to constraint (
        <xref ref-type="bibr" rid="ref7">7</xref>
        ).
      </p>
      <p>This problem is reduced to the problem of maximization by introducing additional
variables y = {0,1}. It looks like this.</p>
      <p>To find:
with restrictions:
Let
,
∀
with restrictions:
∀
∀
.</p>
      <p>Then the solution to the problem of determining the optimal content of the
information support of the ADPS for monitoring the information security of the
informatization object components and their placement in the LAN nodes is reduced
to solving M multidimensional knapsack problems, which are formulated as follows.</p>
      <p>To find:
∀
.</p>
      <p>The result of solving the problem of developing the information support of the
analytical data processing system for monitoring the information security of the
informatization object’s structure is the optimal according to the given criteria
(including the general and / or marginal utility), the composition of the information
support components of ADPS and their placement on the LAN nodes.</p>
      <p>Conclusion</p>
      <p>Thus, in this article, the problem of determining a rational structure of ADPS
for monitoring the information security of an informatization object’s information
support based on modern SIEM systems is considered.</p>
      <p>The formalization and solution of this problem are based on the methods of utility
theory and operations research, which allow using computer modeling to determine
the optimal composition of the ADPS information support components and their
distribution among LAN nodes from the point of view of the general usefulness of
information, taking into account the analytical information technologies used in these
nodes for identifying information security incidents.</p>
      <p>In general, this approach makes it possible to increase the efficiency of the
procedure for identifying information security incidents by organizing a rational exchange
of information between LAN nodes (information protection means), taking into
account the characteristics of analytical data processing procedures.
12. Uralsky N.B., Sizov V.A. Development of a modified genetic algorithm for solving the
problem of parallelizing multiplication of high-dimensional matrices in distributed data
processing systems. In: IX International Scientific and Practical Conference "Innovative
Development of the Russian Economy": in 6 volumes. Moscow: FGBOU VO "PRUE im.</p>
      <p>
        G. V. Plekhanov ", 2016.
13. Mikryukov A.A., Babash A.V., Sizov V.A. Classification of events in information security
systems based on neural network technologies. Open Education. 2019; 23(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ):57- 63. DOI:
https://doi.org/10.21686/1818-4243-2019-1-57-63
      </p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Sizov</surname>
            <given-names>V.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kirov</surname>
            <given-names>A.D.</given-names>
          </string-name>
          <article-title>Problems of SIEM-systems implementation in the practice of information security management of economic entities</article-title>
          . Open education,
          <year>2020</year>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Lee</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kim</surname>
            <given-names>Y.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kim</surname>
            <given-names>J.H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kim</surname>
            <given-names>I.K.</given-names>
          </string-name>
          <article-title>Toward the SIEM architecture for cloud-based security services</article-title>
          .
          <source>Communications and Network Security IEEE Conference</source>
          ,
          <year>2017</year>
          . DOI:
          <volume>10</volume>
          .1109/CNS.
          <year>2017</year>
          .8228696
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <given-names>G.G.</given-names>
            ,
            <surname>El-Barboni</surname>
          </string-name>
          <string-name>
            <given-names>M</given-names>
            ,
            <surname>Debar H</surname>
          </string-name>
          .
          <article-title>New Types of Alert Correlation for Security Information and Event Management Systems</article-title>
          . New Technologies, Mobility and Security IFIP International Conference,
          <year>2016</year>
          . DOI:
          <volume>10</volume>
          .1109/NTMS.
          <year>2016</year>
          .
          <volume>7792462</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Kavanagh</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rochford</surname>
            <given-names>O</given-names>
          </string-name>
          .
          <article-title>Magic Quadrant for Security Information</article-title>
          and
          <string-name>
            <given-names>Event</given-names>
            <surname>Management</surname>
          </string-name>
          .
          <source>Gartner technical report</source>
          .
          <year>2015</year>
          . 15 p.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Markov</surname>
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsirlov</surname>
            <given-names>V.L.</given-names>
          </string-name>
          <article-title>Strukturnoye soderzhaniye trebovaniy informatsionnoy bezopasnosti</article-title>
          .
          <source>Monitoring pravoprimeneniya</source>
          .
          <year>2017</year>
          . №
          <volume>1</volume>
          (
          <issue>22</issue>
          ). P.
          <volume>53</volume>
          -
          <fpage>61</fpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2412</fpage>
          -81632017-1-
          <fpage>53</fpage>
          -61.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Nabil</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Soukainat</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lakbabi</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ghizlane</surname>
            <given-names>O.</given-names>
          </string-name>
          <article-title>SIEM selection criteria for an efficient contextual security</article-title>
          .
          <source>In: 2017 International Symposium on Networks, Computers and Communications (ISNCC)</source>
          ,
          <year>2017</year>
          . DOI:
          <volume>10</volume>
          .1109/ISNCC.
          <year>2017</year>
          .
          <volume>8072035</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Kotenko</surname>
            <given-names>I.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Fedorchenko</surname>
            <given-names>A.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sayenko</surname>
            <given-names>I.B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kushnerevich</surname>
            <given-names>A.G.</given-names>
          </string-name>
          <article-title>Tekhnologii bolshikh dannykh dlya korrelyatsii sobytiy bezopasnosti na osnove ucheta tipov svyazey</article-title>
          .
          <source>Voprosy kiberbezopasnosti</source>
          .
          <year>2017</year>
          . №
          <volume>5</volume>
          (
          <issue>24</issue>
          ). P. 2-
          <fpage>16</fpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456-2017-5-2-16.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Fedorchenko</surname>
            <given-names>A.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Levshun</surname>
            <given-names>D.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chechulin</surname>
            <given-names>A.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kotenko</surname>
            <given-names>I.V.</given-names>
          </string-name>
          <article-title>Analiz metodov korrelyatsii sobytiy bezopasnosti v SIEM-sistemakh. Part 2</article-title>
          .
          <string-name>
            <surname>Trudy</surname>
            <given-names>SPIIRAN</given-names>
          </string-name>
          .
          <year>2016</year>
          . no. 49. P.
          <volume>208</volume>
          -
          <fpage>225</fpage>
          . DOI:
          <volume>10</volume>
          .15622/sp.49.11.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Kirsanov</surname>
            <given-names>K.K.</given-names>
          </string-name>
          <article-title>The theory of utility in the period of conceptual provisions change</article-title>
          .
          <source>Bulletin of Eurasian Science</source>
          .
          <year>2015</year>
          . No.
          <volume>2</volume>
          (
          <issue>27</issue>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Sizov</surname>
            <given-names>V.A.</given-names>
          </string-name>
          <article-title>Models and methods of virtual-restorative data backup of automated information-control systems in emergency situations</article-title>
          .
          <source>Journal of Automation and Telemechanics, No. 7</source>
          ,
          <year>1998</year>
          p.
          <fpage>176</fpage>
          -
          <lpage>184</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Sizov</surname>
            <given-names>V.A.</given-names>
          </string-name>
          <article-title>Development of models for increasing the efficiency of data safety in a distributed computing environment based on dynamic data backup. Collection of articles of the XXI International Scientific</article-title>
          and Practical Conference “
          <source>Advances in Science and Technology"</source>
          . Moscow, Actuality.RF Publ.,
          <year>2019</year>
          . pp.
          <fpage>96</fpage>
          -
          <lpage>100</lpage>
          . URL: http://xn-- 80aa3afkgvdfe5he.
          <fpage>xn</fpage>
          --p1ai/AST-21 originalmaket N.pdf
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>